Medium severity5.5NVD Advisory· Published Oct 8, 2026· Updated Oct 8, 2026
CVE-2026-107730
CVE-2026-107730
Description
SumatraPDF is a multi-format reader for Windows. In 3.7.0.22298, LitParseHeader() in src/LitDoc.cpp computes the attacker-controlled hdrLen + nPieces * 16 section offset using signed 32-bit arithmetic without validating the complete result. When the component values make that aggregate calculation overflow to a negative value, pointer construction reaches an invalid read in LitU32(), causing deterministic application termination. The supplied evidence does not demonstrate code execution, information disclosure, arbitrary read, or integrity impact. No fixed version is available as of this review.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.7.0.22298
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.